Privacy Policy
The short version
- Your full chat never leaves your phone. Roastclub reads your chat export on your device and counts the stats there.
- To write the jokes, the app sends a small digest: those stats plus a few short lines per member, with member names replaced by placeholders such as “Member A”. The digest is processed to write your roast and is not stored.
- There is no account. The app uses an anonymous device identifier so it can give you one free roast, apply fair-use limits and check whether you have Pro.
- Purchases are handled by Apple and RevenueCat. We never see your payment details.
- No ads, no analytics SDKs, no tracking. We do not sell your data.
This policy explains how the Roastclub iOS app (“Roastclub”, “the app”) handles information. Roastclub is made by Gökhan Tosun (“we”, “us”). If you have a question, email gokhan.tosun1995@gmail.com.
Contents
- What stays on your phone
- The roast digest
- Device and purchase identifiers
- What our server keeps, and for how long
- Who processes data for us
- Tracking, ads and analytics
- Phone permissions
- Children
- Your choices and rights
- Deleting your data
- Security
- Where data is processed
- Changes to this policy
- Contact
1. What stays on your phone
When you open a WhatsApp or Telegram chat export in Roastclub, the app reads and analyses it on your device. Every number on your cards (message counts, reply times, double texts, late-night share, top emoji and so on) is calculated on your phone.
- The full chat file is never uploaded. When a file is shared into Roastclub from another app, the copy iOS hands to Roastclub is deleted once it has been read.
- Roastclub does not keep a history of your chats or roasts. The real names in your chat are kept in the app's memory only so they can be put back onto your cards on your phone.
- Card images you share are written to a temporary file for the iOS share sheet, under a neutral file name that never contains a name or chat title.
- The app stores a small number of settings on your phone, such as whether you have finished the introduction screens, and its device identity (see section 3) in the iOS Keychain.
2. The roast digest
The jokes on your cards are written by an AI language model, which runs on a server, not on your phone. To write them, Roastclub sends our server a digest, and only the digest. It contains:
- Stats computed on your phone: for each member, their message count and share, median reply time, double texts, conversations started, longest monologue, late-night share and top emoji; and for the chat, the total number of text messages, the busiest hour and, in a two-person roast, the interest score.
- A few short lines per member: at most 8 messages each, cut to at most 160 characters, for at most 12 members. The whole digest is capped at 24,000 characters.
- The roast type (group or two-person) and the savagery level you picked.
Names are replaced before anything is sent. Every member becomes a placeholder (“Member A”, “Member B”…, or “You” and “Them” in a two-person roast), and those names are replaced inside the lines too. Members you hide from a roast are sent as “Someone”. Links, email addresses, @handles and phone numbers in the lines are replaced with [link], [email], [handle] and [phone]. The swap back to real names happens on your phone.
This replacement is automatic and works on the names in the export. It cannot recognise every way a person can be identified in free text (a nickname, a surname mentioned in passing, a street name), so the short lines may still contain personal details that were in the chat. They may also contain messages written by the other people in the chat, so please only roast chats you are part of.
Why we send it: to generate your roast and to run a safety check on the result (we block jokes about race, religion, sexuality, gender, bodies, health or disability). What happens to it: our server passes the digest to the AI model, receives the jokes, checks them and returns them to your phone. The digest is not saved to our database or written to our logs. Our database keeps only a one-way fingerprint (a SHA-256 hash) of the request, which lets a retried request be recognised so you are never charged twice; the digest cannot be rebuilt from it. That record is deleted after 7 days (section 4).
3. Device and purchase identifiers
Roastclub has no sign-up and no login. Instead it uses Apple's App Attest service to create an anonymous device identity the first time you roast a chat. It consists of:
- an App Attest key identifier and its public key, created by Apple's App Attest service on your device;
- a random device ID our server assigns; and
- a random purchase user ID (it starts with
rcl_) that links your device to your purchases at RevenueCat.
These identifiers contain nothing about you: no name, email, phone number or Apple ID. We use them only to make the app work: to give each device one free roast, to apply fair-use limits, to check whether you have Roastclub Pro, and to prove requests come from the genuine app. Together with your purchase history, they are the data listed on Roastclub's App Store privacy label: Device ID, User ID and Purchase History, linked to you and used for App Functionality only.
The identity is kept in your iPhone's Keychain. Keychain items can survive deleting the app; App Attest keys do not, so after a reinstall the app creates a new identity.
Purchases
Roastclub Pro is an auto-renewing subscription sold through the App Store. Apple processes the payment; we never see your card or payment details. RevenueCat, our subscription provider, receives your purchase records from Apple (product, purchase and expiry dates, and transaction identifiers) under your purchase user ID, so the app and our server can tell whether Pro is active. See Apple's privacy policy and RevenueCat's privacy policy.
4. What our server keeps, and for how long
| Record | What it contains | Kept for |
|---|---|---|
| Device record | App Attest key identifier and public key, a counter used to reject replayed requests, device ID, purchase user ID, whether the free roast has been used, the App Attest environment, creation time | Until you ask us to delete it (section 10), or until we shut the service down |
| Roast record | Device ID, a request key, a one-way hash of the request, roast type, number of members, whether it was free, Pro or a fallback, attempts, timing, the prompt and model version, time. No chat text, names or jokes. | 7 days, then deleted by an hourly clean-up job |
| Rate-limit counters | A count per time window, keyed by device ID, or by your IP address (for IPv6, its first half) for requests made before a device is verified | 2 days, then deleted by an hourly clean-up job |
| Subscription status cache | Whether your purchase user ID currently has Pro | 1 to 5 minutes, then it expires automatically |
| Server logs | Event names, error codes, counts, timings, token counts, model and prompt versions. Our logging code accepts no free text, so it cannot record chat lines, names, jokes or identifiers. | As retained by Cloudflare's platform |
We use your IP address only to limit how many requests can be made from one network, which protects the service from abuse.
5. Who processes data for us
We use these service providers. Each receives only what is listed here.
| Provider | What it receives | Why |
|---|---|---|
| Apple | App Attest key generation and verification on your device; App Store purchases | Verifying the genuine app; payments |
| RevenueCat | Your purchase user ID and purchase records; the RevenueCat software in the app also talks to RevenueCat directly to load prices and restore purchases | Managing subscriptions |
| Cloudflare | Hosts our server, database and these web pages; it handles every request to them, including your IP address | Hosting |
| OpenRouter, and the AI host it routes to (Together AI or Fireworks AI) | The digest described in section 2, and the generated jokes for the safety check. Never your device or purchase identifiers. | Writing and checking your roast |
Our server tells OpenRouter to use only the AI hosts we have chosen, never to fall back to another one, and to use only hosts that, according to OpenRouter, do not collect or train on the data they receive (OpenRouter's “deny data collection” setting). The model is a DeepSeek model, but it is never called through DeepSeek's own service; our server refuses that configuration. These providers process the digest under their own terms: OpenRouter, Together AI, Fireworks AI, Cloudflare.
6. Tracking, ads and analytics
Roastclub does not track you across other companies' apps or websites, does not use the advertising identifier (IDFA), and contains no advertising, analytics, attribution or crash-reporting software. We do not sell or share your personal information for advertising.
7. Phone permissions
- Photos (add only): asked only when you tap Save on a card, so the app can add that image to your library. Roastclub cannot see your photos.
- Files: Roastclub opens only the chat export you pick or share to it.
- Roastclub does not ask for your contacts, location, camera, microphone or notifications.
8. Children
Roastclub is rated 13+ on the App Store and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Roastclub, contact us and we will delete any device and roast records we can find for them.
9. Your choices and rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you may have the right to access, correct, delete or receive a copy of personal information about you, to object to or restrict its use, and to complain to your local data protection authority. We do not sell or share personal information, and we do not use it for automated decisions that have legal or similarly significant effects on you. We do not discriminate against anyone for exercising these rights.
We process the data in this policy because it is needed to provide the app you asked for (performance of a contract) and, for rate limits and abuse prevention, for our legitimate interest in keeping the service available and fair. To exercise a right, email us (section 14).
10. Deleting your data
Because there is no account, there is nothing to log into or close, and most data deletes itself: roast records after 7 days, rate-limit counters after 2 days. Deleting the app removes everything it stored on your phone except the Keychain identity, which iOS may keep.
The device record stays until you ask us to remove it. Email gokhan.tosun1995@gmail.com with the subject “Roastclub data deletion”:
- If you bought Pro, include the order ID from your Apple receipt email (or from reportaproblem.apple.com). We use it to find your purchase user ID at RevenueCat, then delete your device record and your RevenueCat customer record. Deleting your data does not cancel your subscription; cancel it in your iPhone settings first (see Support).
- If you never bought Pro, your device record holds no name, email or purchase, and the app does not show its identifiers, so we usually cannot tell which record is yours. Tell us roughly when you first used the app and we will tell you honestly whether we can find it.
We reply within 30 days.
11. Security
The app talks to our server only over HTTPS. Every roast request is signed with an Apple App Attest key and checked by the server, which rejects requests that do not come from the genuine app. The device identity in the Keychain is readable only by Roastclub, only on this device, and only after it has been unlocked once since restart. No method of storage or transmission is perfectly secure, but we keep what we hold to the minimum described here.
12. Where data is processed
Our server runs on Cloudflare's global network, and its database is located in Western Europe. The AI hosts that process the digest are selected for US hosting. If you live outside these regions, your data is transferred to them; we rely on our providers' standard safeguards for these transfers.
13. Changes to this policy
If what Roastclub collects changes, we will update this page and its “Last updated” date before the change ships. For significant changes we will also say so in the app.
14. Contact
Gökhan Tosun, developer of Roastclub
Email: gokhan.tosun1995@gmail.com